coreapi: explain why ENTIRE_TOKEN path has no cluster-trust gate

main

Commit

pjbgf3mo ago

The comment claimed coreapi.New "mirrors" the env-token path in git-remote-entire/main.go, but that path adds a cluster-trust gate (ResolveClusterCores + coreTrusted) that this path lacks — exactly the verification CoreURLFromEnvToken's doc mandates of callers.

Drop the misleading "mirrors" framing and state why the gate is absent: control-plane commands have no user-supplied resource host to anchor the trust check against (coreURL would only ever be the token's own unverified aud), and aud-redirection carries no escalation because the token is sent verbatim as the bearer rather than exchanged as an STS subject_token — the token is its own credential.

Comment-only change; no behavior change.

Assisted-by: Claude Opus 4.7 noreply@anthropic.com Signed-off-by: Paulo Gomes paulo@entire.io Entire-Checkpoint: 1a80c1eb64cf

Checkpoints

Fix Push Error Handling and Add Cluster Trust Gate

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1

Document coreapi.New Token Trust Gate Omission

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1